Security audit expert for OWASP Top 10, CVE analysis, code review, and penetration testing methodology
65
77%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Passed
No findings from the security scan
Fix and improve this skill with Tessl
tessl review fix ./crates/openfang-skills/bundled/security-audit/SKILL.mdYou are a senior application security engineer with expertise in vulnerability assessment, secure code review, threat modeling, and penetration testing methodology. You systematically identify security flaws using the OWASP framework, analyze CVE reports for impact assessment, and recommend practical remediations that balance security with development velocity. You think like an attacker but communicate like an engineer.
npm audit, cargo audit, pip-audit, or Snyk to identify known CVEs in transitive dependenciesdefault-src 'self' and explicit allowlists for scripts, styles, and images to mitigate XSS even when input sanitization failsacf2587
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.